Privacy Policy
Dear Client, Business Partner, and Employee,
On May 25, 2018, new legislation concerning the protection of personal data came into force. Therefore, we provide you with information on the processing of personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as the “GDPR”), and Act No. 18/2018 Coll. on Personal Data Protection and on amendments to certain acts.
Controller:
Gräper Europe s.r.o., Národná ulica 34, 010 01 Žilina, Slovakia
Company ID: 36 724 084
Email: graeper@graeper.sk
In the course of its activities, the Controller processes personal data for various purposes, most of which are necessary in accordance with applicable legal regulations or international treaties binding on the Slovak Republic.
We would also like to inform you about how we handle your personal data, your rights, and the legal bases for processing personal data. While reviewing the information pursuant to Articles 13 and 14 of the GDPR, you may encounter the following terms:
Definitions
- Consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data.
- Genetic data means personal data relating to inherited or acquired genetic characteristics of a natural person which provide unique information about the physiology or health of that person.
- Biometric data means personal data resulting from specific technical processing relating to physical, physiological or behavioural characteristics enabling unique identification (e.g., facial images or fingerprint data).
- Data concerning health means personal data related to physical or mental health, including information about healthcare services.
- Processing means any operation performed on personal data such as collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure, restriction, erasure, etc.
- Profiling means automated processing used to evaluate personal aspects such as performance, economic situation, health, preferences, behaviour, location, etc.
- Pseudonymisation means processing in a manner that data can no longer be attributed to a specific individual without additional information.
- Log means a record of user activity within an information system.
- Online identifier includes identifiers such as IP address, cookies, login data, etc.
- Information system means any structured set of personal data accessible according to specific criteria.
- Data subject means an identified or identifiable natural person.
- Controller means the entity determining purposes and means of processing personal data.
- Recipient means any entity to whom personal data is disclosed.
- Third party means any entity other than the data subject, controller, or processor.
- Processor means a person processing personal data on behalf of the controller.
- Enterprise means any natural or legal person engaged in economic activity.
- Group of undertakings means a controlling undertaking and its controlled undertakings.
- Main establishment means the central administration within the EU.
- International organisation means an organisation governed by public international law.
- Member State means a state of the EU or EEA.
- Third country means a country outside the EU/EEA.
Purposes of Processing Personal Data
The Controller processes personal data within the following systems:
Employees
- HR and Payroll System
- Registry Management System
- Accounting System
Business Partners and Clients
- Registry Management System
- Accounting System
- Business Partner Database
- Marketing System
Website Visitors
- Cookies System
Rights of the Data Subject
The data subject has the right to:
- Access personal data and obtain confirmation whether data is processed
- Rectification of inaccurate or incomplete data
- Erasure (“right to be forgotten”) under conditions defined by GDPR
- Restriction of processing
- Data portability
- Object to processing, especially for direct marketing
- Not to be subject to automated decision-making, including profiling
- Withdraw consent at any time
The data subject also has the right to lodge a complaint with the supervisory authority:
Office for Personal Data Protection of the Slovak Republic
Hraničná 4826/12, 820 07 Bratislava
Tel.: +421 2 3231 3214
Email: statny.dozor@pdp.gov.sk
Website: https://dataprotection.gov.sk
The data subject may contact the Controller with any requests or questions regarding personal data processing in writing or electronically using the contact details provided above.
